Description
ASUS routers supporting custom OpenVPN profiles are vulnerable to a code execution vulnerability. An authenticated and remote attacker can execute arbitrary operating system commands by uploading a crafted OVPN profile. Known affected routers include ASUS ExpertWiFi, ASUS RT-AX55, ASUS RT-AX58U, ASUS RT-AC67U, ASUS RT-AC68R, ASUS RT-AC68U, ASUS RT-AX86, ASUS RT-AC86U, ASUS RT-AX88U, and ASUS RT-AX3000.
Published: 2024-05-20
Score: 7.2 High
EPSS: 3.1% Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Analysis and contextual insights are available on OpenCVE Cloud.

Remediation

Vendor Solution

Apply the vendor provided firmware update.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2024-16197 ASUS routers supporting custom OpenVPN profiles are vulnerable to a code execution vulnerability. An authenticated and remote attacker can execute arbitrary operating system commands by uploading a crafted OVPN profile. Known affected routers include ASUS ExpertWiFi, ASUS RT-AX55, ASUS RT-AX58U, ASUS RT-AC67U, ASUS RT-AC68R, ASUS RT-AC68U, ASUS RT-AX86, ASUS RT-AC86U, ASUS RT-AX88U, and ASUS RT-AX3000.
History

Sat, 22 Nov 2025 13:15:00 +0000

Type Values Removed Values Added
First Time appeared Asus expertwifi
Asus rt-ac1900
Asus rt-ac1900u
Asus rt-ac2900
Asus rt-ac67u
Asus rt-ac68p
Asus rt-ac88u
Asus rt-ax86 Series
Asus zenwifi Xt8
CPEs cpe:2.3:a:asus:expertwifi:0:*:*:*:*:*:*:*
cpe:2.3:h:asus:rt-ac1900:0:*:*:*:*:*:*:*
cpe:2.3:h:asus:rt-ac1900u:0:*:*:*:*:*:*:*
cpe:2.3:h:asus:rt-ac2900:0:*:*:*:*:*:*:*
cpe:2.3:h:asus:rt-ac67u:0:*:*:*:*:*:*:*
cpe:2.3:h:asus:rt-ac68p:0:*:*:*:*:*:*:*
cpe:2.3:h:asus:rt-ac68r:0:*:*:*:*:*:*:*
cpe:2.3:h:asus:rt-ac68u:0:*:*:*:*:*:*:*
cpe:2.3:h:asus:rt-ac86u:0:*:*:*:*:*:*:*
cpe:2.3:h:asus:rt-ac88u:0:*:*:*:*:*:*:*
cpe:2.3:h:asus:rt-ax3000:0:*:*:*:*:*:*:*
cpe:2.3:h:asus:rt-ax55:0:*:*:*:*:*:*:*
cpe:2.3:h:asus:rt-ax58u:0:*:*:*:*:*:*:*
cpe:2.3:h:asus:rt-ax86_series:0:*:*:*:*:*:*:*
cpe:2.3:h:asus:zenwifi_xt8:0:*:*:*:*:*:*:*
Vendors & Products Asus expertwifi
Asus rt-ac1900
Asus rt-ac1900u
Asus rt-ac2900
Asus rt-ac67u
Asus rt-ac68p
Asus rt-ac88u
Asus rt-ax86 Series
Asus zenwifi Xt8
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Sat, 22 Nov 2025 12:45:00 +0000

Type Values Removed Values Added
First Time appeared Asus
Asus 4g-ac68u
Asus rt-ac68r
Asus rt-ac68u
Asus rt-ac86u
Asus rt-ax3000
Asus rt-ax55
Asus rt-ax58u
Asus rt-ax88u
CPEs cpe:2.3:a:asus:4g-ac68u:*:*:*:*:*:*:*:*
cpe:2.3:h:asus:rt-ac68r:*:*:*:*:*:*:*:*
cpe:2.3:h:asus:rt-ac68u:*:*:*:*:*:*:*:*
cpe:2.3:h:asus:rt-ac86u:*:*:*:*:*:*:*:*
cpe:2.3:h:asus:rt-ax3000:*:*:*:*:*:*:*:*
cpe:2.3:h:asus:rt-ax55:*:*:*:*:*:*:*:*
cpe:2.3:h:asus:rt-ax58u:*:*:*:*:*:*:*:*
cpe:2.3:h:asus:rt-ax88u:*:*:*:*:*:*:*:*
Vendors & Products Asus
Asus 4g-ac68u
Asus rt-ac68r
Asus rt-ac68u
Asus rt-ac86u
Asus rt-ax3000
Asus rt-ax55
Asus rt-ax58u
Asus rt-ax88u

Subscriptions

Asus 4g-ac68u Expertwifi Rt-ac1900 Rt-ac1900u Rt-ac2900 Rt-ac67u Rt-ac68p Rt-ac68r Rt-ac68u Rt-ac86u Rt-ac88u Rt-ax3000 Rt-ax55 Rt-ax58u Rt-ax86 Series Rt-ax88u Zenwifi Xt8
cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2025-11-22T12:25:40.045Z

Reserved: 2024-01-10T15:27:41.121Z

Link: CVE-2024-0401

cve-icon Vulnrichment

Updated: 2024-08-01T18:04:49.502Z

cve-icon NVD

Status : Deferred

Published: 2024-05-20T17:15:09.223

Modified: 2026-04-15T00:35:42.020

Link: CVE-2024-0401

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses